This article explains how Cosign, Kyverno, and Harbor can work together to enforce image signature verification in Kubernetes. The approach is well-suited for enterprise environments with private registries, custom TLS certificates, and restricted access to public transparency logs.
https://medium.com/@hansakabiyon99/enforcing-signed-container-images-in-kubernetes-using-cosign-kyverno-helm-based-setup-646209ecb8ce